| Time & API |
Arguments |
Status |
Return |
Repeated |
1619340497.6405
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
1048576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00990000
|
success
|
0 |
0
|
1619340497.6405
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a50000
|
success
|
0 |
0
|
1619340498.1405
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02410000
|
success
|
0 |
0
|
1619340498.1405
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025f0000
|
success
|
0 |
0
|
1619340498.1875
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619340498.2495
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00580000
|
success
|
0 |
0
|
1619340498.2495
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00590000
|
success
|
0 |
0
|
1619340498.2495
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0051a000
|
success
|
0 |
0
|
1619340498.2495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619340498.2495
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00512000
|
success
|
0 |
0
|
1619340498.5465
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00522000
|
success
|
0 |
0
|
1619340504.0155
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00545000
|
success
|
0 |
0
|
1619340504.0155
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054b000
|
success
|
0 |
0
|
1619340504.0155
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00547000
|
success
|
0 |
0
|
1619340504.3285
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00523000
|
success
|
0 |
0
|
1619340504.3745
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0052c000
|
success
|
0 |
0
|
1619340504.4215
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00790000
|
success
|
0 |
0
|
1619340504.4535
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
1511424
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00802000
|
success
|
0 |
0
|
1619340504.5155
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00791000
|
success
|
0 |
0
|
1619340504.5155
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00524000
|
success
|
0 |
0
|
1619340504.5315
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00792000
|
success
|
0 |
0
|
1619340504.6245
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00793000
|
success
|
0 |
0
|
1619340504.6715
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00525000
|
success
|
0 |
0
|
1619340504.6875
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00794000
|
success
|
0 |
0
|
1619340504.7495
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00795000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00800000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00800000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00800000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00800000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00800000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|
1619340504.7495
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00974000
|
success
|
0 |
0
|